Vulnerability Description
Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Hybridsoftware | Cloudflow | >= 2.0.0, < 2.3.2 |
Related Weaknesses (CWE)
References
- https://csirt.divd.nl/CVE-2022-41217Third Party Advisory
- https://csirt.divd.nl/DIVD-2022-00052
- https://csirt.divd.nl/CVE-2022-41217Third Party Advisory
- https://csirt.divd.nl/DIVD-2022-00052
FAQ
What is CVE-2022-41217?
CVE-2022-41217 is a vulnerability with a CVSS score of 9.8 (CRITICAL). Cloudflow contains a unauthenticated file upload vulnerability, which makes it possible for an attacker to upload malicious files to the CLOUDFLOW PROOFSCOPE built-in storage.
How severe is CVE-2022-41217?
CVE-2022-41217 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2022-41217?
Check the references section above for vendor advisories and patch information. Affected products include: Hybridsoftware Cloudflow.